4 ms·
In a sense, finding security bugs is a very specialized QA sub-discipline, which often requires a far deeper understanding about security than many QA engineers
by muricula 4y ago
In a sense, finding security bugs is a very specialized QA sub-discipline, which often requires a far deeper understanding about security than many QA engineers or developers possess. However, there is also a part of that organization which does feature work to systemically address the kinds of security issues they find.
Also, many large organizations like MS don't have many QA teams, preferring to push QA tasks onto developers, but still need specialized security teams. If you dig into the deep history of morse, they barely escaped being sacked when MS laid off the QA org circa 2017.
(I used to work on that team, but now work at another company doing a similar job)
- jamesfinlayson 4y agoAgreed - none of the QAs I have ever worked with have done security testing (unless called out in the test plan). One of the companies I have worked for does annual penetration tests which seems reasonable.